Q: Your Terraform module is creating resources but you want to ensure all resources have specific tags (owner, environment, cost-center). How do you enforce this?
Option 1: Default tags (AWS provider)
#Terraform #Security & Best Practices #L3 #IaC #Cloud Infrastructure
🎙️ Candidate Opening & Architectural Context
""Managing infrastructure as code across multiple teams requires disciplined state management and locking. When addressing this question, I walk the interviewer through our production incident runbook: isolating the blast radius, checking diagnostic logs and metrics, and applying a safe fix.""
Advertisement
🛠️ Production Runbook & Step-by-Step Resolution
1️⃣
Production Solution & Architecture
Option 1: Default tags (AWS provider) All resources created by this provider automatically get these tags. Option 2: Variable merge pattern Option 3: Policy enforcement — OPA/Conftest rule that fails if any resource is missing required tags.
provider "aws" {
default_tags {
tags = {
Environment = var.environment
Owner = var.team
ManagedBy = "Terraform"
}
}
}
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: Option 1: Default tags (AWS provider)."
⚡ 60-Second Elevator Pitch Talking Points
- Immediate Triage: Option 1: Default tags (AWS provider)
- Run targeted verification commands before modifying configuration.
- Automate permanent guardrails (CI check, alerts, IaC policy) to prevent recurrence.
Advertisement